CTA Practice Questions
Prepare for CTA with more than an answer.
- Exam fee
- $7000 USD
- Level
- Expert
- Valid for
- Annual maintenance required
Domains covered on the exam 9
- CMDB and CSDM15%
- Technical Governance6%
- Testing Leading Practices15%
- Go-Live Preparation6%
- Security Architecture15%
- Data Strategies11%
- Current and To-Be Architecture9%
- Platform Data and Integrations15%
- Release and Instance Strategy8%
- 1
A company has a primary production instance and a dedicated, isolated instance used exclusively for end-user training and sandbox activities. What is the main architectural advantage of this dedicated training instance strategy?
Show answer details
Correct answer: B
The primary advantage is isolation. A dedicated training instance prevents user training, testing of new features by non-developers, or general sandbox experimentation from interfering with structured development, testing, and production operations. This ensures that the development lifecycle is not disrupted by unpredictable activities, accidental data changes, or performance degradation caused by training exercises.
- 2
Company Background:
HealthFirst is a large healthcare provider with a complex ecosystem of clinical applications, including an Electronic Health Record (EHR) system, a lab information system (LIMS), and a patient scheduling system. They are implementing ServiceNow ITOM Health to gain visibility into the operational status of these critical services. The goal is to create real-time service health dashboards for the IT operations center.Current Situation:
The EHR system is a modern, cloud-based application that provides a REST API for status updates. The LIMS is an older, on-premises system that writes status events to a log file. The patient scheduling system sends SNMP traps when it encounters errors. The CMDB is partially populated but lacks relationships between the infrastructure CIs and the application services.Requirements & Constraints:
- Create a single, consolidated health dashboard for the 'Clinical Services' portfolio.
- The solution must use ServiceNow-native tools where possible.
- Alerts must be automatically correlated to the correct Application Service CI.
- The solution must not require custom code to be written inside the legacy systems.
- The implementation must follow CSDM principles.
Which combination of ServiceNow features and architectural steps is required to meet these objectives?
Show answer details
Correct answer: C
This option presents a complete, best-practice architectural approach. 1) It starts with CSDM to create the foundational data model, which is essential for service-aware operations. 2) It correctly identifies that ITOM Event Management has native connectors for various data sources (REST, Log File, SNMP), meeting the 'no custom code in legacy systems' requirement. 3) It leverages Alert Management rules, a key feature of ITOM, to perform the automatic correlation of events to the CIs defined in the CSDM model. This comprehensive strategy directly addresses all stated requirements.
- 3
When defining a data ownership strategy within a Technical Governance framework, what is the primary role of a 'Data Steward'?
Show answer details
Correct answer: B
A Data Steward is a business or functional role, not a technical one. They are accountable for the quality, definition, and lifecycle of a specific set of data. For example, the manager of the server team might be the Data Steward for all Server CIs. They ensure the data is accurate, complete, and properly managed according to the governance policies. The Data Owner is typically a senior executive with ultimate accountability, while developers perform the technical implementation.
- 4
A project team is preparing for the go-live of a new ServiceNow application. The architect emphasizes the need for a well-structured communication plan. What is the primary objective of the 'pre go-live' communication phase?
Show answer details
Correct answer: B
The pre go-live communication phase is focused on organizational change management. Its purpose is to inform stakeholders about what is changing, why it's changing, when it will happen, and how it will affect them. This builds awareness and excitement, sets clear expectations, and ensures users are prepared and trained before the system is launched, which is crucial for successful user adoption.
- 5
An architect is designing a solution that requires a visual representation of the logical components of the system and their relationships, independent of the underlying physical infrastructure. This artifact needs to be easily understood by both business analysts and developers. Which type of diagram would be most appropriate for this purpose?
Show answer details
Correct answer: C
A C4 model component diagram is specifically designed to show the logical components within a container (e.g., an application or microservice) and their interactions. It abstracts away the physical infrastructure, focusing on the logical structure, which makes it ideal for communication between business analysts, architects, and developers. A network diagram focuses on physical infrastructure, an ERD on data structure, and a sequence diagram on time-based interactions, not logical structure.
- 6
A manufacturing company uses a third-party cloud service for its inventory management. The architect needs to build an integration that allows ServiceNow to retrieve inventory levels on demand. The third-party service provides a well-documented REST API. Which ServiceNow component is the preferred, low-code solution for building this type of outbound integration?
Show answer details
Correct answer: C
IntegrationHub, used within Flow Designer, is ServiceNow's primary low-code solution for building reusable integrations. For a standard outbound REST call, an architect would create a REST action in IntegrationHub. This action can then be easily incorporated into a flow, allowing for complex logic to be built around the integration without extensive scripting. Scripted REST APIs are for inbound integrations. Outbound SOAP is for the older SOAP protocol. A scripted include is a pro-code approach and not the preferred low-code solution.
- 7
An architect is presented with the following diagram representing a customer's current architecture for handling inbound incidents from a monitoring tool. The customer is complaining about high maintenance costs and slow response to changes. Based on architectural best practices, what is the primary issue with this design?
graph TD subgraph ServiceNow A[Email Inbound Action] --> B{Create Incident}; end subgraph Monitoring Tool C(Alert Triggered) --> D[Send Formatted Email]; end D --> A; subgraph Other Systems E(System E) --> F[Send Email]; G(System G) --> H[Send Email]; end F --> A; H --> A;Show answer details
Correct answer: B
The diagram clearly shows that multiple external systems are all funneled through a single point of failure: an email inbound action. Email parsing is inherently brittle; a small change in the email format from any source can break the integration. It lacks robust error handling, has no mechanism to send a success/failure response back to the source system, and is generally considered a poor practice for system-to-system integration. A modern approach would use REST APIs (e.g., the Incident API or a Scripted REST API) which are structured, reliable, and support response codes.
- 8
A global pharmaceutical company is implementing ServiceNow to manage clinical trial data. They are required by regulations like HIPAA and GDPR to ensure that Personally Identifiable Information (PII) is not viewable by ServiceNow support personnel, even when they require access to the instance for troubleshooting. The solution must not impact the usability of platform features like global search or reporting on non-sensitive fields. Which security architecture component is specifically designed to meet this requirement?
Show answer details
Correct answer: D
Edge Encryption is the correct solution. It encrypts data at the customer's network boundary before it is sent to the ServiceNow cloud. This means ServiceNow personnel, including support, never have access to the unencrypted data or the encryption keys. This approach meets the strict regulatory requirements while preserving platform functionality like searching and reporting on non-encrypted fields. SNC Access Control manages access for support but doesn't encrypt the data. RBAC is for internal user access. Database encryption protects data at rest within ServiceNow's data centers, but support personnel with access could still potentially view it.
- 9
A large retail organization is migrating from a legacy, on-premises ITSM tool to ServiceNow ITSM Pro. The project includes migrating over 10 million incident, problem, and change records. The legacy data format is inconsistent and requires significant cleansing and field mapping. The technical architect must design a data import strategy that minimizes performance impact on the production instance during the import process and provides robust logging for troubleshooting. Which ServiceNow feature should be the core component of this strategy?
Show answer details
Correct answer: B
The Robust Transform Engine (RTE) is specifically designed for large-scale data imports. It isolates the transformation and processing functions from the platform's primary schedulers, which minimizes performance impact on the instance. It also provides detailed, step-by-step logging and error handling, which is crucial for troubleshooting complex data migrations. While concurrent import sets can speed up imports, RTE is the underlying technology that provides the required performance isolation and robustness.
- 10
A consultant is designing a testing strategy for a custom ServiceNow application that will be used by thousands of global users. The application has complex workflows that interact with multiple external systems via IntegrationHub. The client has mandated that any regression defects must be identified before they reach UAT. What are the key non-functional testing practices the architect must include in the plan to ensure application stability and scalability? (Select THREE)
Show answer details
Correct answer: B, C, E
Performance, Load, and Security testing are critical non-functional tests for an application with these requirements. Performance testing checks the speed and responsiveness. Load testing simulates concurrent user access to ensure stability under stress. Security testing identifies vulnerabilities in the custom code and integrations. While Usability testing is important, it's a functional aspect. Unit testing is a developer-level activity focused on individual code components, not the overall application stability and scalability.
